CVE

Id
43778  
CVE No.
CVE-2010-1194  
Status
Candidate  
Description
The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.  
Phase
Assigned (20100330)  
Votes
None (candidate not yet proposed)  
Comments